CVE-2026-64549: Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
Published Jul 27, 2026
·Updated
Bluetooth: bpa10x: avoid OOB read of revision string in bpa10xsetup()
Affected Software
2 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1
Event History
Jul 27, 2026
CVE Published
via MITRE·08:10 PM
Data Sourced
via MITRE·08:10 PM
Description
Data Sourced
via NVD·09:17 PM
Description
Aug 7, 2026
Data Sourced
via Microsoft·07:18 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:18 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64549?
CVE-2026-64549 has a severity score of 15, indicating a critical security risk.
2
How do I fix CVE-2026-64549?
To fix CVE-2026-64549, update your Linux kernel to the latest version that addresses this vulnerability.
3
What does CVE-2026-64549 affect?
CVE-2026-64549 affects the Bluetooth protocol implementation in the Linux kernel.
4
What kind of vulnerability is CVE-2026-64549?
CVE-2026-64549 is an out-of-bounds (OOB) read vulnerability in the bpa10x setup function.
5
Is there a known exploit for CVE-2026-64549?
As of now, there are no publicly known exploits for CVE-2026-64549.